Subject: Re: /etc/passwd.conf
To: Todd Vierling <tv@pobox.com>
From: Sean Davis <dive@endersgame.net>
List: tech-security
Date: 08/05/2003 16:41:16
On Tue, Aug 05, 2003 at 11:19:36AM -0400, Todd Vierling wrote:
> On Tue, 5 Aug 2003, Jun-ichiro itojun Hagino wrote:
> 
> : 	given that DES is crackable in 3 seconds, i would like to propose the
> : 	following change.  you can still use DES password entries, it only
> : 	affects newly-created entries (like by passwd(1)).  what do people
> : 	think?  (ypcipher is kept to "old" for backward compat)
> 
> This was brought up some time ago.  The result was that the default is
> selectable in sysinst, and the copy in src/etc/passwd.conf is intentionally
> left commented out.
> 
> Rather than changing src/etc/passwd.conf, which will be blown away by
> sysinst, you probably want to add a Blowfish option to sysinst.

IIRC, sysinst in -current has a blowfish option. I picked it when installing
-current on an Alpha recently.

-Sean

-- 
/~\ The ASCII
\ / Ribbon Campaign                   Sean Davis
 X  Against HTML                       aka dive
/ \ Email!